Crypto Regulation Reform
Mr. President, I am watching with great interest the activity with regard to cyrpto regulation and have an observation I would like to share. The following was excerpted from the Harris statement:
The President has determined that vital U.S. national security and law enforcement interests compel maintaining appropriate control of encryption. Still, there is much that can be done to reform existing controls to ensure that they are efficiently implemented and to maintain U.S. leadership in the world market for encryption technology. Accordingly, the President has asked the Secretary of State to take immediate action to implement a number of procedural reforms. The reforms are:
While I totally understand the concern here and am in sympathy with the reasoning, assuming benign adherence to the procedures, I think you are in effect jousting windmills with this attempt to control or regulate crypto. It is simply too easy to build and distribute inexpensive devices that are *truly secure*, without back doors to make it other than delusional to think that the people that we would not want to have this technology won't. A device can be made right now at lower cost than a computer modem, much lower, that could be inserted between any phone and the wall that would make it impossible, no matter what laws are in place, to tap either passively or acitively, communication that passes between two of these devices. I know how to do it, could do it and probably will just for the fun of it at least. If I can there are many others that can also. In fact I personally know several. These devices can be credit card size and even fit in a wallet. They can easily be smuggled in and will be. A black market will flourish and nothing will have been accomplished except the expenditure of a lot of futile money and creation of more crime in an inflated, lucrative market. We simply must accept that point-to-point secure communication is a part of our electronic environment and swallow the bitter pill that no matter what the valid arguments are for regulation, it is effectively not possible, so that national security and law enforcement are going to be denied, in the near future, a tool in their arsenel and will have to come up with new ways of gathering this intelligence. Please abandon this effort before we throw good money after bad and create a worse situation than we will have without it. I would like whoever processes this email to forward a copy to the following contact.
The contact point for further information on these reforms is Rose Biancaniello, Office of Defense Trade Controls, Bureau of Political-Military Affairs, Department of State, (703) 875-6644.
Sincerely, Bob Cain -- Bob Cain rcain@netcom.com 408-354-8021
Robert Cain writes:
A device can be made right now at lower cost than a computer modem, much lower, that could be inserted between any phone and the wall that would make it impossible, no matter what laws are in place, to tap either passively or acitively, communication that passes between two of these devices. I know how to do it, could do it and probably will just for the fun of it at least.
Uhh, could you tell us? Sounds like quite a breakthrough. Credit card sized? Much cheaper than a modem, like $50 maybe? And it digititizes and securely encrypts speech (full duplex?) on the fly? -- | GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com> | | TAKE TWA TO CAIRO. ||| Tivoli Systems, Austin, TX: | | (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |
Mike McNally sez:
Robert Cain writes:
A device can be made right now at lower cost than a computer modem, much lower, that could be inserted between any phone and the wall that would make it impossible, no matter what laws are in place, to tap either passively or acitively, communication that passes between two of these devices. I know how to do it, could do it and probably will just for the fun of it at least.
Uhh, could you tell us?
'Fraid not. I want to patent it and profit from it. As a hardware/software development engineer I stand diametrically opposed to the FSF gang.
Sounds like quite a breakthrough. Credit card sized? Much cheaper than a modem, like $50 maybe? And it digititizes and securely encrypts speech (full duplex?) on the fly?
Well, making it credit card sized and cheaper than a modem is not all that difficult. An AT&T VSELP chip based on their DSP1616 with some firmware added for primative modem capability, some firmware for the encryption and a couple of codec chips fits the bill nicely. I do have a breakthrough though and that is in the area of a key exchange protocol that can detect an active spoof, a problem unsolvable in theory (at least in the opinion of Whit Diffie, Marty Hellman and Ron Rivest) but solvable to any desired degree of confidence in practice. In fact in the most common situation that I would expect it to be used, it is provably secure against a spoof. I can't say any more about how that works but some fine mathematicians and some crypto names most of you know have witnessed and validated it. Peace, Bob -- Bob Cain rcain@netcom.com 408-354-8021 "I used to be different. But now I'm the same." --------------PGP 1.0 or 2.0 public key available on request.------------------
Robert Cain says:
A device can be made right now at lower cost than a computer modem, much lower, that could be inserted between any phone and the wall that would make it impossible, no matter what laws are in place, to tap either passively or acitively, communication that passes between two of these devices. I know how to do it, could do it and probably will just for the fun of it at least.
Uhh, could you tell us?
'Fraid not. I want to patent it and profit from it. As a hardware/software development engineer I stand diametrically opposed to the FSF gang.
There are exactly two ways to transmit a signal. Either you are in the digital or the analog domain. If you are in the digital domain, you need a modem, so your device can't be cheaper than a modem. If you are in the analog domain, you can't get good encryption short of extremely iffy techniques. (You could, for instance, have a DES chip putting out data that was used to control analog scramblers, but synching up the two sides would be hard and waveform information might be used to reconstruct the signal even without breaking the sequence.) Given that V.32 class modems are only a couple hundred bucks, and will soon be only a hundred bucks or so, its hard to imagine how anything analog that was decent could be cheaper anyway.
Well, making it credit card sized and cheaper than a modem is not all that difficult. An AT&T VSELP chip based on their DSP1616 with some firmware added for primative modem capability, some firmware for the encryption and a couple of codec chips fits the bill nicely.
You still need a modem. You therefore cannot be cheaper than a modem.
I do have a breakthrough though and that is in the area of a key exchange protocol that can detect an active spoof, a problem unsolvable in theory (at least in the opinion of Whit Diffie, Marty Hellman and Ron Rivest) but solvable to any desired degree of confidence in practice.
This would not make your machine cheaper., and anyone wanting real security will sign their Diffie-Hellman exchanges anyway.
In fact in the most common situation that I would expect it to be used, it is provably secure against a spoof.
Can't be done without shared data, because without shared data you have no way of even knowing who you are talking to.
I can't say any more about how that works but some fine mathematicians and some crypto names most of you know have witnessed and validated it.
Oh? .pm
Perry E. Metzger sez:
Robert Cain says:
Well, making it credit card sized and cheaper than a modem is not all that difficult. An AT&T VSELP chip based on their DSP1616 with some firmware added for primative modem capability, some firmware for the encryption and a couple of codec chips fits the bill nicely.
You still need a modem. You therefore cannot be cheaper than a modem.
Once again, what we call a modem today has gobs of bells and whistles in firmware and hardware that a simple voice->bits->wierd-bits->anlog and it's inverse is a whole lot simpler at many levels than today's modems. In fact it doesn't even require 9600 baud with CELP or VSELP which is wonderful since overseas sessions at that speed are iffy at best I have found. Compare the price of a 4800 baud modem today with what we now call "modems."
I do have a breakthrough though and that is in the area of a key exchange protocol that can detect an active spoof, a problem unsolvable in theory (at least in the opinion of Whit Diffie, Marty Hellman and Ron Rivest) but solvable to any desired degree of confidence in practice.
This would not make your machine cheaper., and anyone wanting real security will sign their Diffie-Hellman exchanges anyway.
No, not cheaper, just viable. :-)
In fact in the most common situation that I would expect it to be used, it is provably secure against a spoof.
Can't be done without shared data, because without shared data you have no way of even knowing who you are talking to.
We shall see. I contend that with this I can establish a spoof-proof point to point with a total stranger to any desired probability that a spoof could not be there without disclosing him/her. It is not hard for me to envision, especially in business situations, how such a thing would be more than useful. There really is no point in arguing this until I can present it. There are two reasons I mentioned it. The first is that I wanted to see if there have been any other breakthroughs in the time I have had this on the shelf and the second reason is private. :-)
I can't say any more about how that works but some fine mathematicians and some crypto names most of you know have witnessed and validated it.
Oh?
Yep. Peace, Bob -- Bob Cain rcain@netcom.com 408-354-8021 "I used to be different. But now I'm the same." --------------PGP 1.0 or 2.0 public key available on request.------------------
Earlier, Robert Cain wrote:
We shall see. I contend that with this I can establish a spoof-proof point to point with a total stranger to any desired probability that a spoof could not be there without disclosing him/her. It is not hard for me to envision, especially in business situations, how such a thing would be more than useful.
If I understand you correctly, your asserting that without _any_ prior knowledge of the person you are communicating to, and without any form of online checks before or during your authentication mechanism, that you can be _sure_ you're talking to said stranger ? Unless there are other presumptions, I fail to see how you can be sure you are communicating to someone, when you don't know who they are. Even if you can get something akin to a pgp key with an identifier and be sure you are taking to the owner of _that_ identifier, but you can't be sure that identifier is real and/or not a forgery. Given those circumstances, wouldn't a man in the middle relay attack be a piece of cake ? Matthew. -- Matthew Gream. ph: (02)-821-2043. M.Gream@uts.edu.au. PGPMail and brown paperbags accepted.
Matthew Gream writes:
Earlier, Robert Cain wrote:
We shall see. I contend that with this I can establish a spoof-proof point to point with a total stranger...
If I understand you correctly, your asserting that without _any_ prior knowledge of the person you are communicating to, and without any form of online checks before or during your authentication mechanism, that you can be _sure_ you're talking to said stranger ?
If Mr. Cain needs somebody to spearhead his marketing campaign, I'm sure this feature would be enough to convince L. Detweiler to provide his services pro bono. -- | GOOD TIME FOR MOVIE - GOING ||| Mike McNally <m5@tivoli.com> | | TAKE TWA TO CAIRO. ||| Tivoli Systems, Austin, TX: | | (actual fortune cookie) ||| "Like A Little Bit of Semi-Heaven" |
Mike McNally sez:
Matthew Gream writes:
Earlier, Robert Cain wrote:
We shall see. I contend that with this I can establish a spoof-proof point to point with a total stranger...
If I understand you correctly, your asserting that without _any_ prior knowledge of the person you are communicating to, and without any form of online checks before or during your authentication mechanism, that you can be _sure_ you're talking to said stranger ?
If Mr. Cain needs somebody to spearhead his marketing campaign, I'm sure this feature would be enough to convince L. Detweiler to provide his services pro bono.
Love it! I don't know the full Detweiler story, could someone fill me in via email? I missed Matthew's post somehow but, yes, I am asserting that you can be speaking with someone you have not spoken to before and can go secure at any point in the conversation. You can see how useful this could be to business. Many large companies have spent bundles on secure phone systems within their organizations yet are still vulnerable when making calls across company boundries. With my widget it's quite easy to provide this in a distributed way, only to those individuals that require it and it crosses company boundries securely as well. Until the full functionality is in an ASIC, the cost, while lower than a computer modem, is still not yet what a large mass of the public would dish out so I am counting on business from business to make it cheap enough to be easily affordable by folks like you and I. BTW I agree totally with an earlier post that all I have presented so far is vapor and unsubstantiated assertions. Why bother talkin' at all now when I've been sittin' on it for a year? I really do have my reasons and they are objective, some having to do with fear of "interference" from the fed. Perhaps more on them in the future. All will become clear. :-) Peace, Bob -- Bob Cain rcain@netcom.com 408-354-8021 "I used to be different. But now I'm the same." --------------PGP 1.0 or 2.0 public key available on request.------------------
Mike McNally says:
Robert Cain writes:
A device can be made right now at lower cost than a computer modem, much lower, that could be inserted between any phone and the wall that would make it impossible, no matter what laws are in place, to tap either passively or acitively, communication that passes between two of these devices. I know how to do it, could do it and probably will just for the fun of it at least.
Uhh, could you tell us? Sounds like quite a breakthrough. Credit card sized? Much cheaper than a modem, like $50 maybe? And it digititizes and securely encrypts speech (full duplex?) on the fly?
By definition anything that does this in the digital domain needs a modem, so it can't be cheaper than a modem. None of the analogue methods are going to be terribly secure. .pm
Perry E. Metzger sez:
Uhh, could you tell us? Sounds like quite a breakthrough. Credit card sized? Much cheaper than a modem, like $50 maybe? And it digititizes and securely encrypts speech (full duplex?) on the fly?
By definition anything that does this in the digital domain needs a modem, so it can't be cheaper than a modem. None of the analogue methods are going to be terribly secure.
Remember that a "modem" such as we are used to is a much more complex device (at least the firmware, and you do pay for that :-) than what is required for simply modulating and demodulating a fixed rate, framed bit stream. Today's modem chip sets invariably have a general purpose microprocessor to do all the Hayes type stuff and a DSP to do the actual bit stream modulation/demodulation (and digital filtering and echo cancelation, etc.) where my device can be the DSP alone and requires no RS232 ports or the like. This will result in a saving. In short, what is required for a voice-only device such as I am initially thinking about is a subset of what is required for a computer modem. Peace, Bob -- Bob Cain rcain@netcom.com 408-354-8021 "I used to be different. But now I'm the same." --------------PGP 1.0 or 2.0 public key available on request.------------------
Robert Cain says:
Perry E. Metzger sez:
Uhh, could you tell us? Sounds like quite a breakthrough. Credit card sized? Much cheaper than a modem, like $50 maybe? And it digititizes and securely encrypts speech (full duplex?) on the fly?
By definition anything that does this in the digital domain needs a modem, so it can't be cheaper than a modem. None of the analogue methods are going to be terribly secure.
Remember that a "modem" such as we are used to is a much more complex device (at least the firmware, and you do pay for that :-) than what is required for simply modulating and demodulating a fixed rate, framed bit stream.
This is embarassingly wrong, Robert.
Today's modem chip sets invariably have a general purpose microprocessor to do all the Hayes type stuff and a DSP to do the actual bit stream modulation/demodulation (and digital filtering and echo cancelation, etc.) where my device can be the DSP alone and requires no RS232 ports or the like. This will result in a saving.
Have you actually looked at one of the Rockwell chipsets in real use, Robert? They have "all in one" solutions these days. Getting cheaper than what they sell is almost impossible -- you cannot achieve savings by "leaving things out" because there is nothing available to leave out. With the cost of a codec to do something like QCELP and the chip to do the encryption, you are going to be at least as expensive as a normal modem anyway just for the parts to manage that component of the work.
In short, what is required for a voice-only device such as I am initially thinking about is a subset of what is required for a computer modem.
I'd be very suprised to see your price predictions come true. I'd be less suprised to see a secure voice product becaue the mechanisms to build such things are well understood and hardly revolutionary. .pm
Perry E. Metzger sez:
Robert Cain says:
Remember that a "modem" such as we are used to is a much more complex device (at least the firmware, and you do pay for that :-) than what is required for simply modulating and demodulating a fixed rate, framed bit stream.
Perry E. Metzger sez: This is embarassingly wrong, Robert.
Please embarass me. Do you always approch things with the hostility I am sensing, Perry? I've heard this about you but this is the first time I've run into it myself. :-)
Have you actually looked at one of the Rockwell chipsets in real use, Robert? They have "all in one" solutions these days. Getting cheaper than what they sell is almost impossible -- you cannot achieve savings by "leaving things out" because there is nothing available to leave out. With the cost of a codec to do something like QCELP and the chip to do the encryption, you are going to be at least as expensive as a normal modem anyway just for the parts to manage that component of the work.
Yes, every chip set and DSP on the market in excruciating detail. It was only recently that I realized that I could use a simpler, cheaper solution. I'm an EE as well as programmer and I've actually got bills of materials and schematics for this. I'm not guessing.
I'd be very suprised to see your price predictions come true. I'd be less suprised to see a secure voice product becaue the mechanisms to build such things are well understood and hardly revolutionary.
And I'll be very happy to surprise you when the political dust has settled, when I am satisfied that a patent filing isn't going to be stamped so that even I can't look at it or talk about it legally and when I find the bucks to patent it and build one. I keep saying I won't argue and then I do. :-) Time for me to put up or shut up. I've tested these waters to my satisfaction and from the feedback here believe that my solution is still non-obvious (until you see it :-) So, I'll be back to discuss this further when I can freely. Later, Bob -- Bob Cain rcain@netcom.com 408-354-8021 "I used to be different. But now I'm the same." --------------PGP 1.0 or 2.0 public key available on request.------------------
Robert Cain says:
Please embarass me. Do you always approch things with the hostility I am sensing, Perry?
No, but I've got a shock proof shit detector and you are triggering it. One of the things that sets it off is odd claims being made before implementation. You are making a very odd claim, which is that you can beat the price on a Rockwell integrated modem module by building something yourself -- given the economies of scale, a weird statement. You are also claiming that given that you need to have a DSP doing your modem work, and processing power to do your cryptography and DSP horsepower to do your vocoder, you are still going to be able to beat the price of mass-market modems that are falling to the $100 range with your non-mass market product. Frankly, it sounds like a load of crap. I might be wrong, of course -- I've been wrong before. However, when people make strange claims to me about things they haven't finished implementing yet that they don't sell, especially after they've made lots of mistakes in their postings the previous week, it sets off alarm bells in my head. I'm not saying its impossible, but I'm saying that until you give me more evidence I'm not going to think that your claim is credible, and I don't think any other reasoning person should, either.
Yes, every chip set and DSP on the market in excruciating detail. It was only recently that I realized that I could use a simpler, cheaper solution. I'm an EE as well as programmer and I've actually got bills of materials and schematics for this. I'm not guessing.
When you have the product in hand and can actually sell it for less than a modem, please get back to us. Right now, its vaporware. .pm
Robert Cain says:
Please embarass me. Do you always approch things with the hostility I am sensing, Perry?
No, but I've got a shock proof shit detector and you are triggering it. One of the things that sets it off is odd claims being made before implementation. You are making a very odd claim, which is that you can beat the price on a Rockwell integrated modem module by building
That's not what he said. He said 'modem', and as a consumer item that's far from a 'Rockwell integrated modem module'... That part is a small part of the whole price of the modem, which you'd know if you looked at price sheets. For a 99 modem (which I see all the time with 14400 fax/data), the modem chip is probably $15-20. The accepted minimum markup on a manufactured item is 50% of selling price. Of course, you can cut the margin if you sell enough of them, and it's hard to say what the manuf. margin on a $99 modem is. In anycase, he's talking about a slower modem, effectively, using a DSP (Zyxels, which beat most modems on features and performance have always used DSP's: they do data, fax, voice, callerid, touch tone recognition, etc. They include a 68K and >512K ram (I think)).
something yourself -- given the economies of scale, a weird statement. You are also claiming that given that you need to have a DSP doing your modem work, and processing power to do your cryptography and DSP horsepower to do your vocoder, you are still going to be able to beat the price of mass-market modems that are falling to the $100 range with your non-mass market product. Frankly, it sounds like a load of crap. I might be wrong, of course -- I've been wrong before. However, when people make strange claims to me about things they haven't finished implementing yet that they don't sell, especially after they've made lots of mistakes in their postings the previous week, it sets off alarm bells in my head. I'm not saying its impossible, but I'm saying that until you give me more evidence I'm not going to think that your claim is credible, and I don't think any other reasoning person should, either.
Well, he certainly might not succeed, but it sounds plausible to me. sdw -- Stephen D. Williams Local Internet Gateway Co.; SDW Systems 513 496-5223APager LIG dev./sales Internet: sdw@lig.net sdw@meaddata.com OO R&D Source Dist. By Horse: 2464 Rosina Dr., Miamisburg, OH 45342-6430 Comm. Consulting ICBM: 39 34N 85 15W I love it when a plan comes together
participants (5)
-
m5@vail.tivoli.com -
mgream@acacia.itd.uts.edu.au -
Perry E. Metzger -
rcain@netcom.com -
sdw@meaddata.com